Kajika

joined 3 years ago
[–] Kajika@lemmy.ml 2 points 1 day ago

Instead of contributing to (fascist) US companies I'd love to see people looking at alternative to the big companies we have right not.

We should look at manufacter are actually trying to be better, more considerate with people (all the people not just the west) and the environment.

In the tech space no one cares or no one dares to raise their voice against the big companies, their anti-consumer policies, their green-washing and definitely their genocidal fascist ideology.

Yes probably thinkpad are good laptops. If you're on a budget just do whatever you can, if you buy System76 you are not "on a budget".

2 companies I know of that seems to go on a better path than most I see in comments here are slimbook (https://slimbook.com/) and maybe Tuxedo (https://www.tuxedocomputers.com/).

We should be better than this.

[–] Kajika@lemmy.ml 2 points 2 days ago (1 children)

Fascism is the concept this guy is lacking in order to describe what's happening here, and its consequence: imperialism.

Oh wait,, wikipedia:

Vardi is open about his Zionism and is listed as a signatory on an anti-academic-boycott letter “United Against the Academic Boycott of Israel,” that denies that genocide has ever occurred in Palestine, despite an inquiry by a United Nations Independent International Commission and International Association of Genocide Scholars stating that the legal definition of genocide has been met according to the Genocide Convention. Vardi supports a two-state solution and served 5 years in the Israel Defense Forces, participating in two wars during his service. Vardi has remarked that boycotts against Israel on university campuses are "deeply distasteful".

He is fascist after all, Wow.

[–] Kajika@lemmy.ml 1 points 2 days ago (1 children)

Yes you are right, damned! Why git isn't signing the diff (patch)? This is so wrong on so many level, signing already hash the content, we can sign multiple GiB without any issue.

[–] Kajika@lemmy.ml 3 points 2 days ago* (last edited 2 days ago) (6 children)
[–] Kajika@lemmy.ml 1 points 2 days ago* (last edited 2 days ago) (3 children)

~~Indeed it is still relevant~~. I am wondering what does it sign for tags.

EDIT: Are you sure about that? signing the hash felt logical but digging about it this seems a false assumption. git is signing the whole commit object.

[–] Kajika@lemmy.ml 6 points 3 days ago* (last edited 3 days ago) (6 children)

Security is achieved through other means.

Let's explicit this: you can, and should, sign your commits if you want security (no commit tampering). You need to:

  • generated a gpg key: gpg --full-generate-key
  • set git to look for the public key to use: git config --global user.signingkey [public key ID]
  • set git to sign your commits: git config --global commit.gpgsign true

Note that I used --global here but you can do without to sign on a per-project basis.

Also gpg UX is terrible, to find the [public key ID] use the command gpg --list-keys, it should looks like:

pub   ed25519 2026-01-01 [SC] <- type algorithm date and capability (this key is only to Sign and Certify)
      662E3CDD6FE329002D0CA5BB40339DD82B12EF16 <- Public key ID
uid           [ultimate] my full name (Master Key) <my_email@domain.com> <- owner information (should be your name and email address)
sub   rsa4096 2026-01-01 [E] <- sub key used to encrypt
sub   ed25519 2026-01-01 [S] [expires: 2027-01-01] <- subkey used to sign

Last, if you want to save/backup you keys the default location of gpg files is ~/gnupg or you can export keys with gpg --export [key ID] > path/to/file.key for the public part and gpg --export-secret-keys [private key ID] for the private part. Both export can have a -a or --armor argument to output as base64 text instead of raw binary. [private key ID] can be found with gpg --list-secret-keys.

EDIT: after writing this I checked https://git-scm.com/book/en/v2/Git-Tools-Signing-Your-Work and TIL you can sign tags too.

EDIT 2: you can also use your ssh key to sign -> git config --global gpg.format ssh (I am less inclined to do this as you won't have subkeys and expiration date but this would be simplier indeed)

[–] Kajika@lemmy.ml 3 points 6 days ago (1 children)

Thanks for sharing.

Why didn't I know lobsters before? This look 1000 times better than HN... oh you can't join. Makes sense it isn't that known.

[–] Kajika@lemmy.ml 6 points 6 days ago* (last edited 6 days ago) (2 children)

It's sad to see this community only listening to people because they're rich: there are a lot of better engineers who knows more than this guy but they're not "co-creator of GitHub". I read this title as boot licking silicon valley.

That being said you don't hash git commits for security reason : YOU SIGN YOUR COMMITS FOR SECURITY. Sorry for the caps but let's make this visible.

[–] Kajika@lemmy.ml 1 points 1 week ago

Is this even legal to not identify yourself while selling a product?

[–] Kajika@lemmy.ml 10 points 1 week ago

I salute the initiative but to be honest I'd prefer a lemmy instance by a long mile (actually always looking for lemmy instances deferated from all the noise).

I can't stand the discourse UX and I am pretty sure that, like slack, this is a black hole where any message in the middle is lost forever (no one will read them).

[–] Kajika@lemmy.ml 7 points 1 week ago (4 children)

AI slop, the guys pretends to be software engineer and outputting posts every day. This is extremely low quality, no wonder he advocates not avoiding AI.

[–] Kajika@lemmy.ml 10 points 1 week ago

Y combinator is deeply rooted in fascism, I'm trying to find the hacker-news post that shocked me about "going back to silicon-valley root: the military industry". The "liberal-progressive" tone that can be read from commenters can soften the overall vibe but in the end the tone is definitely not great : last example for me was how the "stopomarchy" news was treated (flagged, and the comments smells very bad) : https://news.ycombinator.com/item?id=49661901

It's been 2 years now that on top of this the vast majority of "news" are LLM related. And if you're not into that this make the website not worth anything any more.

view more: next ›